OpenAI · OpenAI Privacy Policy · View original document ↗

User Rights and Data Subject Access Requests

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time OpenAI changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity OpenAI recorded 24 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for OpenAI Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy discloses a set of data subject rights including access, rectification, deletion, restriction, portability, consent withdrawal, and complaint rights, available depending on the user's jurisdiction. Requests can be submitted through the account interface, privacy.openai.com, or by email to dsar@openai.com.

This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the mechanisms through which users can exercise statutory data rights. The policy qualifies all listed rights with 'depending on where you live,' which means the availability of each right depends on the user's jurisdiction and applicable law rather than being uniformly available to all users.

Recent Activity

This document changed recently

Medium Jun 12, 2026

The updated policy explicitly discloses that OpenAI receives information from advertisers and other data partners for Free and Go users, and uses this data to personalize ads and measure ad effectiveness. The policy now states that Free and Go users can control what data OpenAI uses to personalize ads through advertising controls in account settings. This represents clarified disclosure of an existing practice rather than a new authorization.

View change record →
Medium Jun 7, 2026

The updated privacy policy now explicitly states that OpenAI receives information from advertisers and other data partners, which is used to personalize ads shown to Free and Go users and to measure the effectiveness of those ads. For example, the policy notes that OpenAI could receive information about purchases users make from advertisers. The policy now includes a dedicated section on ad personalization and measurement as a primary use of personal data for these user tiers. You can manage what data OpenAI uses for ad personalization by accessing the advertising controls in your account settings or by using the Data Controls option.

View change record →
Medium May 1, 2026

The updated policy now explicitly authorizes OpenAI to promote products and services to users through direct marketing on third-party properties and to share limited information with select marketing partners (who are not service providers) to support these efforts. The policy states that some marketing partners may receive information through cookies and similar technologies. The revised terms establish that these marketing practices are subject to user choices and controls, with additional information and opt-out options available. You can make choices about the use of your information for third-party product promotion purposes through controls referenced in the policy.

View change record →

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, users may exercise access, deletion, correction, portability, restriction, and consent withdrawal rights through the account interface, the privacy portal at privacy.openai.com, or by emailing dsar@openai.com, subject to the jurisdictional availability of each right and applicable verification requirements.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Export Your Data
    Visit privacy.openai.com or email dsar@openai.com to submit a request to access, export, correct, or delete your personal data. Identity verification may be required. Authorized agents must provide signed written permission.

Cross-platform context

See how other platforms handle User Rights and Data Subject Access Requests and similar clauses.

Compare across platforms →

Monitoring

OpenAI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Depending on where you live, you may have certain statutory rights in relation to your Personal Data. For example, you may have the right to: Access your Personal Data and information relating to how it is processed. Rectify or update your Personal Data Delete your Personal Data from our records. Restrict how we process your Personal Data. Transfer your Personal Data to a third party (right to data portability). Withdraw your consent—where we rely on consent as the legal basis for processing. Lodge a complaint with your local data protection authority. You can exercise some of these rights through your OpenAI account using the tools described in the Data controls section, or you can submit your request through privacy.openai.com or to dsar@openai.com.

Excerpt from OpenAI's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: The rights listed engage GDPR (Articles 15-21 for EEA users via a separate policy), CCPA and CPRA (California), and comprehensive privacy statutes in multiple US states including Colorado, Connecticut, Virginia, Texas, and others. The inclusion of a right to lodge complaints with data protection authorities directly references GDPR Article 77. The FTC and State Attorneys General are relevant enforcement authorities for US-based rights. Appeal rights (referenced in the Additional US State Disclosures section) engage state-level administrative requirement frameworks. 2) GOVERNANCE EXPOSURE: Low to Medium. The provision includes a verification requirement before rights requests are honored, which is standard but may create friction in accessing rights in practice. The policy acknowledges that ChatGPT-generated inaccurate information about a person can be requested for correction or removal, but notes that this is subject to applicable law and technical model capabilities, which may limit the practical scope of correction rights for AI-generated outputs. 3) JURISDICTION FLAGS: The universal qualification 'depending on where you live' means users in jurisdictions without comprehensive privacy legislation may have limited access to some rights. California residents have the broadest disclosed rights set, including appeal rights and authorized agent submission. The separate EEA/UK policy governs GDPR rights for those users. 4) CONTRACT AND VENDOR IMPLICATIONS: Organizations that submit data subject access requests on behalf of their employees or customers should note the authorized agent requirement: the agent must present signed written permission, and the data subject may also be required to independently verify their identity with OpenAI. This dual verification requirement may affect the operability of B2B rights request workflows. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should map each listed right against applicable jurisdictional requirements and confirm that the verification and authorized agent procedures meet the standards of each relevant law. Response timelines are not specified in this policy text and should be confirmed against the operational SLAs for dsar@openai.com processing.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • State AG
    State Attorneys General in California and other states with comprehensive privacy statutes have enforcement authority over data subject rights compliance
    File a complaint →
  • FTC
    The FTC has authority over consumer data rights and unfair or deceptive practices related to privacy
    File a complaint →

Provision details

Document information
Document
OpenAI Privacy Policy
Entity
OpenAI
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-013572
Document ID
CA-D-00010
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c0c49f013e1bb2dd1fa883d161d2b79a60a5914fddbd230bcaa0df5e2cfaa86e
Analysis generated
July 9, 2026 03:28 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenAI
Document: OpenAI Privacy Policy
Record ID: CA-P-013572
Captured: 2026-07-09 03:28:49 UTC
SHA-256: c0c49f013e1bb2dd…
URL: https://conductatlas.com/platform/openai/openai-privacy-policy/provision/CA-P-013572/user-rights-and-data-subject-access-requests/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does OpenAI's User Rights and Data Subject Access Requests clause do?

This provision establishes the mechanisms through which users can exercise statutory data rights. The policy qualifies all listed rights with 'depending on where you live,' which means the availability of each right depends on the user's jurisdiction and applicable law rather than being uniformly available to all users.

How does this clause affect you?

Under this clause, users may exercise access, deletion, correction, portability, restriction, and consent withdrawal rights through the account interface, the privacy portal at privacy.openai.com, or by emailing dsar@openai.com, subject to the jurisdictional availability of each right and applicable verification requirements.

Is ConductAtlas affiliated with OpenAI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.